GDPR compliance checklist
A practical guide to GDPR for teams that don't have a DPO on staff. Lawful bases, data subject rights, DPIAs, records of processing and breach notification — without the legal jargon.
A practical guide to GDPR for teams that don't have a DPO on staff. Lawful bases, data subject rights, DPIAs, records of processing and breach notification — without the legal jargon.
The General Data Protection Regulation (EU 2016/679, and the UK GDPR + Data Protection Act 2018 mirror it) governs how organisations collect, use, store and share personal data of people in the EU and UK. It applies whether you have an office there or not — what matters is whether you process the data of people there.
Penalties are real: up to €20 million or 4% of global annual turnover, whichever is higher. But most enforcement starts with a complaint or a breach — and most fines reward organisations that can show they tried to do the right thing.
GDPR isn't an island. Most of its security requirements (Article 32) are covered by ISO 27001 Annex A controls — run them together and you cut the documentation burden in half.
ISO-STANDARD.app ships a ready-to-adopt GDPR workspace with the risk register, controls catalogue, policies and audit-ready exports already wired together — no spreadsheet sprawl, no consultant lock-in.
Prefer a conversation? Email hello@iso-standard.app — a real human responds within one business day.